Auditing the actual code would build far more trust than any third-party certification. That's the real win here for security-conscious deployments.